squid-3.1.10-22.AXS4
エラータID: AXSA:2014-517:03
Description :
Squid is a high-performance proxy caching server for Web clients,
supporting FTP, gopher, and HTTP data objects. Unlike traditional
caching software, Squid handles all requests in a single,
non-blocking, I/O-driven process. Squid keeps meta data and especially
hot objects cached in RAM, caches DNS lookups, supports non-blocking
DNS lookups, and implements negative caching of failed requests.
Squid consists of a main server program squid, a Domain Name System
lookup program (dnsserver), a program for retrieving FTP data
(ftpget), and some management and client tools.
Security issues fixed with this release:
CVE-2013-4115
Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 through 3.2.11 and 3.3 through 3.3.6 allows remote attackers to cause a denial of service (memory corruption and server termination) via a long name in a DNS lookup request.
CVE-2014-3609
** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Please see below CVEs links for more information.
update packages.
Buffer overflow in the idnsALookup function in dns_internal.cc in Squid 3.2 through 3.2.11 and 3.3 through 3.3.6 allows remote attackers to cause a denial of service (memory corruption and server termination) via a long name in a DNS lookup request.
HttpHdrRange.cc in Squid 3.x before 3.3.12 and 3.4.x before 3.4.6 allows remote attackers to cause a denial of service (crash) via a request with crafted "Range headers with unidentifiable byte-range values."
N/A
SRPMS
- squid-3.1.10-22.AXS4.src.rpm
MD5: 5d391cc368e174ba763f6302b70a7423
SHA-256: 61ceb3ecc3d465dc3e6d66df904f81508dae0530a48dc3dd545c47332db79ae7
Size: 2.45 MB
Asianux Server 4 for x86
- squid-3.1.10-22.AXS4.i686.rpm
MD5: cbc4a1c44cd4bdb5cf124efa3f32430d
SHA-256: 1b6da6ded88eff683a9bf9592b45ec7f512158753d83df7f02c4e40a1d27e13f
Size: 1.73 MB
Asianux Server 4 for x86_64
- squid-3.1.10-22.AXS4.x86_64.rpm
MD5: 7644c53d67ec93528df214894a04fddf
SHA-256: 5a79a714c1b4a98f73ec5dd529720667936b1fc890700abd491cd2c0d4819ac0
Size: 1.73 MB